A while back @mintynet had his car stolen in a keyless theft. He called me in as a #canbus guru to help work out how exactly the car was stolen, and now we know exactly how they did it and also how to stop them. We call it "CAN Injection 🚘💉" and I've written the whole story up in a blog post: https://kentindell.github.io/2023/04/03/can-injection/
CAN Injection: keyless car theft

This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging the cables.

Ken Tindell’s blog
@kentindell
That's pretty interesting. I worked with smart headlight designs, though further up the signal chain than the headlight ECU. For the OEM we worked with, they were very concerned about the security implications of our device (which was related to the illumination). I've seen more OEMs and Tier 1s asking the right questions which is good in the long run, but still leaves millions of vehicles on the road today vulnerable.
@mintynet